
CCIE Security
Domain 4Objective 18
4.18 Cisco IBNS 2.0 (C3PL) for Authentication, Access Control, and User Policy Enforcement CCIE-SECURITY Practice Questions (Page 9)
Part of the 4.0 Identity Management, Information Exchange, and Access Control domain, which accounts for 25% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–1 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
7concepts
25%of the exam
Questions 41–45
- 41
A company is implementing IBNS 2.0 to enforce different access policies for employees and contractors on the same wired switch. The RADIUS server (Cisco ISE) returns a downloadable ACL (dACL) for contractors that restricts access to a specific server subnet. The switch must apply this dACL only to contractor sessions. In the C3PL policy map, where should the dACL be referenced to ensure it is applied after successful authentication?
Select an answer first - 42
A network architect is explaining IBNS 2.0 to a colleague. Which of the following are true about IBNS 2.0 architecture? (Select all that apply.)
Select an answer first - 43
A hospital uses IBNS 2.0 with Cisco ISE to enforce compliance for staff laptops. The security policy requires that if a laptop fails posture assessment, it must be placed in a quarantine VLAN and reauthenticated every 10 minutes until it becomes compliant. The network engineer is configuring the C3PL policy map. Which action should be configured to enforce the 10-minute reauthentication for non-compliant sessions?
Select an answer first - 44
A network admin is troubleshooting an IBNS 2.0 deployment where 802.1X authentication is failing for all users. The switch logs show 'RADIUS server not responding' and the RADIUS server is reachable via ping. The switch is configured with a RADIUS server group. What is the most likely cause of the authentication failure?
Select an answer first - 45
A service provider is designing a new IBNS 2.0 solution for a multi-tenant building. Each tenant must have its own authentication policy and VLAN assignment. The design must use a single switch and a single RADIUS server. Which IBNS 2.0 component is essential to differentiate policies per tenant?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.